Courseiva

SOA-C02 Networking and Content Delivery Practice Question

An organization uses Amazon CloudFront to serve static content from an S3 bucket. The content is updated frequently, but users are seeing stale files. What is the most efficient way to invalidate the cache for updated objects?

⚠ Common exam trap

SOA-C02 often tests the misconception that changing cache headers or S3 metadata retroactively purges already-cached objects — candidates must remember that only an explicit invalidation (or a new cache key) removes content already stored at edge locations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudFront invalidation for the updated files.

CloudFront caches objects at edge locations based on the cache key (path, headers, query strings). When origin content changes, the edge cache still serves the old object until TTL expires. Creating an invalidation explicitly purges the specified paths from all edge locations, forcing CloudFront to fetch fresh content from the S3 origin on the next request. This is the fastest, most targeted way to serve updated files without waiting for TTL expiry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a CloudFront invalidation for the updated files.

    Why this is correct

    CloudFront invalidation is the designed mechanism to force edge locations to discard the cached copies of specified files immediately. When you submit an invalidation for the updated objects, CloudFront stops serving the stale versions and fetches the current ones from the S3 origin on the next request. This is a targeted, low-overhead operation that does not disrupt the distribution or require any configuration changes, making it the correct approach.

  • ✗

    Use the S3 console to set a new cache-control header.

    Why it's wrong here

    Setting a new cache-control header through the S3 console changes the metadata that CloudFront receives on future origin fetches, but it does not retroactively purge objects already cached at edge locations. Because CloudFront caches the object content and its TTL independently until it expires or is invalidated, stale copies will continue to be served until their existing TTL passes. Thus, this action only affects subsequent requests after the old cache entries have expired, not the immediate refresh required.

  • ✗

    Change the origin path in the CloudFront distribution.

    Why it's wrong here

    Changing the origin path in the CloudFront distribution redirects requests to a different directory or bucket prefix, but the previously cached objects from the old path remain stored at edge locations and are still served until their TTL expires. Moreover, modifying the origin path affects all requests and requires a distribution update, which can cause a brief propagation delay and inconsistency. This approach does not selectively refresh the updated files and introduces unnecessary operational risk.

  • ✗

    Delete and recreate the CloudFront distribution.

    Why it's wrong here

    Deleting and recreating the CloudFront distribution removes the existing cache, but it also discards the distribution ID, DNS endpoints, and any associated configurations such as alternate domains, SSL certificates, and behaviors. This forces a full redeployment with a new distribution, causing downtime and requiring customers to repoint DNS, while invalidation would achieve the same cache clearance in minutes. It is an unnecessarily destructive and time-consuming method for updating content.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.